ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Moltbook data leak exposes API tokens, private messages and weak authentication controls

Moltbook, an experimental social platform built around interactions between artificial intelligence agents, has secured a misconfigured database after a data leak exposed API authentication tokens, private messages and tens of thousands of email addresses, raising concerns about both security practices and the authenticity of activity on the platform.


Security researchers at Wiz, a cloud security company, identified a publicly accessible Supabase database that allowed full read and write access to Moltbook’s production data. The exposure included approximately 1.5 million API authentication tokens, around 35,000 registration email addresses and about 4,000 private direct messages exchanged between AI agents.


The issue was disclosed privately to Moltbook, and access to the database was restricted within hours. The researchers described their investigation as non-intrusive, noting that the exposed Supabase API key could be discovered within minutes by a regular user and would have allowed a more technically skilled actor to alter or extract all platform data.


Moltbook has drawn widespread attention on social media in recent days after its AI agents appeared to engage in complex behaviors, including forming belief systems and discussing humanity without apparent human involvement. The platform was created by founder Matt Schlicht, who has publicly said the service was “vibe coded,” meaning the system architecture was conceived by a human but the code itself was generated by AI tools.


The exposed database highlighted systemic weaknesses common in rapidly assembled applications, particularly those using Supabase, which is popular for its ease of setup. The researchers found that API keys and secrets were embedded in client-side code, making them visible through basic inspection, and that security policies were insufficiently restricted.


Among the exposed data were API keys for all registered AI agents, email addresses associated with those registrations and limited identification information. The leak also included 4,060 private messages between agents, some of which contained shared OpenAI API keys.


The findings also challenge assumptions about how autonomous Moltbook’s agents really are. Although the platform is marketed as being accessible only to AI agents, the database showed that it was trivial for humans to register and post while appearing to be agents. While 35,000 email addresses were present in the data, researchers estimate they likely represent about 17,000 individuals. Despite platform rules limiting each person to a single agent, basic requests could be used to register an effectively unlimited number.


More significantly, the same weaknesses allow users to impersonate any existing AI agent through simple API calls, meaning individual posts and conversations could have been fabricated. That revelation casts doubt on some of Moltbook’s most publicized episodes, which drew attention from prominent technology figures including Elon Musk and Andrey Karpathy. The surge of attention also coincided with a sharp rise in the value of a Moltbook-related memecoin.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543